GCFA Windows Artifact Analysis Practice Question
An analyst is investigating a Windows 10 system and discovers that a user's NTUSER.DAT registry hive contains a key named 'RecentDocs' with numerous entries. What is the primary forensic significance of this artifact?
⚠ Common exam trap
The trap here is assuming that RecentDocs contains timestamps or hashes, when it actually only lists recently accessed file and folder names, typically organized by extension.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It maintains a list of recently accessed files and folders, which can indicate user browsing activity and potential data exfiltration.
RecentDocs provides a list of recently accessed files and folders, which is valuable for understanding user activity and potential data exfiltration. It does not include hashes, execution times, or last access timestamps, so the correct interpretation is that it indicates browsing activity and accessed documents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It stores the complete file path and SHA-256 hash of every document opened by the user.
Why it's wrong here
RecentDocs does not store cryptographic hashes of files. It only records the file names and sometimes the extension-based subkeys. Hashes are typically found in other artifacts like Amcache or SRUM. Therefore, this option is incorrect because it misrepresents the data stored in RecentDocs.
- ✓
It maintains a list of recently accessed files and folders, which can indicate user browsing activity and potential data exfiltration.
Why this is correct
RecentDocs keys under NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs store lists of recently opened documents and folders, organized by file extension. They provide evidence of user activity, such as which files were accessed, and can help establish a timeline of user interactions. This is valuable for identifying potential data exfiltration or unauthorized access to sensitive files.
- ✗
It records the most recently opened documents and folders, including the last access time and the application used to open them.
Why it's wrong here
RecentDocs does track recently opened documents and folders, but it does not store the last access time or the application used. It primarily stores the file names and extensions, with limited metadata. The last access time is not a standard field in RecentDocs; that information might be found in other artifacts like LNK files or Jump Lists. Thus, this option overstates the artifact's contents.
- ✗
It tracks the execution time of applications associated with the opened documents.
Why it's wrong here
RecentDocs does not track application execution times. It is focused on document and folder access, not application execution. Execution times are recorded in artifacts like Prefetch, UserAssist, or Sysmon logs. This option confuses the purpose of RecentDocs with that of execution artifacts.
About these practice questions
One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.